Staying a Step Ahead: Mitigating the DPRK IT Worker Threat
ID: b7d5218a-ac23-5d52-af69-283255f29f55
STIX ID: report--b7d5218a-ac23-5d52-af69-283255f29f55
Feed Name: Google Cloud Threat Intelligence
Mandiant outlines UNC5267 — a DPRK IT workforce using stolen identities and fabricated resumes to obtain legitimate corporate access, often routing connections through laptop farms, IP-based KVMs, and VPN services (e.g., Astrill). The report catalogs observed remote administration tools, behavioral indicators (reluctance to use video, shipping laptops to facilitator locations), recommended vetting and technical controls, and warns of ongoing, financially motivated state-aligned intrusions targeting Western organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
